Legal challenges to transatlantic data frameworks aren’t just a headline for compliance teams to track. They can trigger emergency vendor risk reviews and force migration planning many enterprises haven’t budgeted for.
Anchoring your AI and cloud infrastructure in an autonomous European legal entity removes this specific dependency from your risk picture entirely. The next legal development becomes something your team monitors on its own schedule, not something that forces an emergency response.
TL;DR
The EU-US Data Privacy Framework is the third transatlantic data transfer arrangement in a decade to come under serious legal pressure. No court has struck anything down yet, but the pattern deserves your attention regardless of the outcome. The question to ask: does your AI infrastructure depend on this framework, or does it sit outside it entirely?
A pattern worth removing now, not later
Safe Harbor lasted fifteen years before the European Court struck it down in 2015. Its replacement, Privacy Shield, lasted four years before the same court struck that down too, in 2020 [1]. The current arrangement, the EU-US Data Privacy Framework, took effect in 2023 [2]. It’s now three years old and already under renewed legal pressure.
That’s not a pattern most infrastructure leaders would accept from a vendor. It’s worth asking why it’s been acceptable from a legal framework instead.
We’re writing about this because we think the default reaction, watch and wait, gets this exactly backward. Two frameworks have already failed for the same underlying reason. Waiting for a third failure isn’t caution. It’s delay with better PR.
This piece answers one specific question: does your AI infrastructure depend on a legal framework that needs replacing every few years, or does it sit outside that cycle entirely? Below is what happened in the latest ruling, what’s confirmed versus what’s still contested, and where that leaves you.

What happened to the EU-US Data Privacy Framework
On June 29, 2026, the US Supreme Court ruled in Trump v. Slaughter that the president can remove Federal Trade Commission commissioners at will. The 6-3 decision overturned a 90-year-old precedent that had protected the FTC’s independence [3].
The case itself concerns US separation of powers, not data protection. But the Data Privacy Framework rests on a specific assumption: that the FTC acts as an independent enforcement body Europeans can trust to oversee how their data is handled once it crosses the Atlantic. That assumption just lost its legal footing [4].
Privacy law scholars Daniel Solove and Berin Szóka flagged this exact dependency back in March 2025, well before the ruling, when the president first moved to remove FTC commissioners. Both warned at the time that it put the entire adequacy decision at risk [5]. The June 2026 ruling confirmed what they’d already warned about over a year earlier.
What’s confirmed, and what isn’t yet
It’s worth being precise here, because the accurate version of this story is concerning enough without exaggeration. No court has annulled the Data Privacy Framework. What has happened is that noyb, the privacy organization founded by Max Schrems, sent a formal letter to the European Commission on June 30, 2026, urging a withdrawal from the framework and arguing that its legal foundation no longer holds [6]. That’s a policy push, not a lawsuit, at least not yet.
Industry watchers have started using the term “Schrems III” to describe an anticipated future legal challenge. The label has existed informally since 2023, and it’s drawing renewed attention now [7].
Two frameworks struck down. A third one openly discussed. Nothing formally filed yet. That’s exactly the kind of ambiguity that makes “wait and see” feel reasonable, and exactly why waiting is the wrong call.
The question underneath the legal one
It’s easy to focus only on whether the DPF survives and lose sight of the decision actually in front of you. Whatever happens next in this litigation, every IT leader running AI workloads should be asking a separate, structural question right now: does your infrastructure depend on a legal mechanism that’s currently being contested, or does it sit outside that mechanism entirely?
That’s an infrastructure question, and you can answer it today, regardless of how the Commission responds to noyb’s letter or what a future court eventually decides.
What removing the dependency looks like
At Leaseweb, every national entity has operated as a separate, distinct operating entity since 1997, with our global headquarters in Amsterdam governing that structure. Your data, hosting, and processing stay inside a European legal boundary because the entity handling them answers to European jurisdiction in the first place, not because of a treaty that depends on the independence of a foreign regulator you have no visibility into.
That doesn’t make Leaseweb immune to geopolitics. No company is. What it does is remove one specific, currently contested dependency from your compliance picture, so the next headline about the DPF is something you read with interest rather than something that forces your team into action.
We think that’s the actual measure of resilience worth optimizing for. Not immunity from geopolitics, but how many of your infrastructure dependencies you’ve actually chosen, versus how many you’ve simply inherited by never asking. For more on how sovereignty and resilience fit together in practice, see our related article on data sovereignty and resilience.
Where this leaves you
Imagine the Commission actually withdraws from the DPF. Not hypothetical anymore, but a real policy decision. Some of your infrastructure would barely notice. Some of it would be scrambling for a legal basis to keep operating within days.
The question worth sitting with isn’t whether the DPF survives its third challenge. It’s which of those two categories your infrastructure falls into today. And whether that was a choice you made on purpose, or a dependency you inherited by never asking.
Three questions get you to an honest answer faster than a hypothetical does:
- What would it cost your business if your primary cloud vendor had to alter its data transfer protocols overnight? Do you have an estimate today, or would this be the first time you calculated it?
- Does your infrastructure roadmap let you change hosting jurisdiction without rewriting your core application code?
- Who legally governs the entity handling your data: a local subsidiary under European jurisdiction, or a foreign parent company under a legal framework now facing a renewed legal challenge?
You make that decision either way: on purpose, or by default.